CVE-2023-41078
published 2023-09-27CVE-2023-41078: An authorization issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14. An app may be able to bypass certain Privacy…
PriorityP422medium5.5CVSS 3.1
AVLACLPRNUIRSUCNIHAN
EPSS
0.27%
18.7th percentile
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14. An app may be able to bypass certain Privacy preferences.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 14.0 | 14.0 |
| apple | macos | >= unspecified < 14 | 14 |
| apple | macos_sonoma | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2023-41078: macOS Sonoma 14
vendor_apple·2023-09-26·CVSS 5.5
CVE-2023-41078 [MEDIUM] CVE-2023-41078: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-41078
Component: Screen Sharing
Impact: An app may be able to bypass certain Privacy preferences
Description: An authorization issue was addressed with improved state management.
GHSA
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
ghsa·2026-04-18
CVE-2026-41078 [MEDIUM] CWE-400 OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
### Summary
> [!IMPORTANT]
> There is no plan to fix this issue as `OpenTelemetry.Exporter.Jaeger` was deprecated in 2023. It is for informational purposes only.
`OpenTelemetry.Exporter.Jaeger` may allow sustained memory pressure when the internal pooled-list sizing grows based on a large observed span/tag set and that enlarged size is reused for subsequent allocations. Under high-cardinality or attacker-influenced telemetry input, this can increase memory consumption and potentially cause denial of service.
### Details
The Jaeger exporter conversion path can append tag/event data into pooled list structures. In affected versions, pooled allocation sizing may be influ
GHSA
GHSA-r2x6-4xhx-p3qc: An authorization issue was addressed with improved state management
ghsa_unreviewed·2023-09-27
CVE-2023-41078 [MEDIUM] CWE-863 GHSA-r2x6-4xhx-p3qc: An authorization issue was addressed with improved state management
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14. An app may be able to bypass certain Privacy preferences.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-09-27
Published